GDPR & Data Protection Statement
Last updated: 23 June 2026 · Dogma Group Limited (trading as goatelevate.com)
Dogma Group Limited (trading as goatelevate.com) is committed to protecting personal data and complying with the UK GDPR, the EU GDPR, and the Data Protection Act 2018. This statement summarises how we meet those obligations; it sits alongside our Privacy Policy, Cookie Policy, and Data Processing Agreement.
1. Our two roles
- As a controller — for personal data we collect through our website, marketing, demo requests, newsletter, and customer and agency accounts. How we handle this is set out in our Privacy Policy.
- As a processor — when the Service processes personal data within the content and data sources a customer makes available to optimise, publish and monitor it, we act only on that customer's documented instructions. This is governed by our Data Processing Agreement.
2. The principles we apply
We process personal data lawfully, fairly and transparently; only for specified purposes; limited to what is necessary; kept accurate; retained no longer than needed; and held securely. We can demonstrate our compliance (accountability).
3. How the Service is designed for data protection
- Data minimisation by design. The Service processes only the content and data sources a customer chooses to connect or upload, for the purpose of optimising and publishing it. Customer content is not used to train AI models at our layer or at our AI sub-processors.
- Human-in-the-loop publishing. Nothing is published without approval through the Review stage, with a full audit trail. There is no autonomous publishing.
- Customer and client isolation. Each customer's workspace is logically isolated, and agency clients are separated within the white-label portal so one client cannot see another's data.
- Publication boundary. Approved content is published to public surfaces by design; source records in connected systems (such as CRM, billing or inventory) are used only to populate approved content and are not themselves published.
- Data residency. The Service is hosted on Microsoft Azure UK-region infrastructure, and customer data at rest remains in the UK. To generate AI optimisations, relevant content is transmitted to our AI sub-processors for inference under the safeguards in section 5. Where in-region processing is required, AI inference can be configured to run within the UK/EU.
- Security. Encryption in transit (TLS 1.2+) and at rest (AES-256), multi-factor authentication, role-based access control, Microsoft Intune device management, Microsoft Purview data loss prevention, and Microsoft Defender for Endpoint threat monitoring.
4. Sub-processors
To deliver the Service we rely on the following sub-processors:
Sub-processor | Role | Location & safeguards |
|---|---|---|
Microsoft Corporation (Azure) | Hosting and platform | UK data centres |
Content-delivery / edge provider | Global delivery of published public content | Available on request |
AI sub-processors (OpenAI, Anthropic, Google) | AI analysis and optimisation (AEO / GEO) | UK IDTA / EU SCCs; no model training |
Dogma International Pvt. Ltd | Technical delivery and support | Nepal; access via UK-based VDI only — data remains in the UK |
We notify customers of changes to sub-processors at least 14 days in advance as set out in the DPA and impose equivalent data-protection obligations on each by contract. A full, current list is maintained in our Sub-processor List.
5. International transfers
Where personal data is transferred outside the UK or EEA — for example, to an AI sub-processor that processes content in another region — we rely on appropriate safeguards such as adequacy decisions, the UK International Data Transfer Agreement or UK Addendum, and the EU Standard Contractual Clauses. Where required, we assess transfer risks and apply supplementary technical and organisational safeguards. Copies of relevant safeguards are available on request, subject to confidentiality and commercial restrictions.
6. Data subject rights
Individuals may exercise their rights to access, rectification, erasure, restriction, portability, and objection. Requests relating to website or marketing data go to enquiries@goatelevate.com. Requests relating to content processed on a customer's behalf are handled by that customer as controller; we assist them as required by the DPA.
7. Breach notification
We maintain procedures to detect, investigate and report personal data breaches. Suspected breaches are escalated internally within two hours of detection. Where we act as a processor, we notify the affected customer within 24 hours. Where we act as a controller, we notify the relevant supervisory authority within 72 hours where required.
8. Data protection impact assessment
Because the Service involves large-scale automated processing of content, which may include personal data, through AI, and the publication of that content, customers should consider whether a Data Protection Impact Assessment under Article 35 UK GDPR is required for their deployment. We provide reasonable assistance with this.
9. Governance
Data protection is led by our IT System and Infrastructure Lead. General privacy enquiries go to enquiries@goatelevate.com. You may also complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
